Blocking Top-Level Navigations to Data URLs for Firefox 58
blog.mozilla.org
blog.mozilla.org
security.insecure_connection_icon.enabled
security.insecure_connection_icon.pbmode.enabled
Though it's still disabled by default (currently the insecure connection icon is only shown if a password field is present on a http page / the form action url is http).
Since the download happens locally it also will not be logged in your perimeter monitoring and most security appliances do not inspect inline HTML especially from “trusted” domains due to performance limitation.
I’ve used this trick to bypass DLP, local policies and various content filtering appliances multiple times.
[0] https://addons.mozilla.org/en-US/firefox/addon/offlineqr/
-t {PNG,EPS,SVG,ANSI,ANSI256,ASCII,ASCIIi,UTF8,ANSIUTF8}
specify the type of the generated image. (default=PNG)We generate SVG graphs in the browser, and have a button with a data:image/svg+xml URL to allow users to download these graphs, for example to include in a publication.
> Whereas the following cases will be allowed:
> • Downloading a data: URL, e.g. ‘save-link-as’ of “data:…”
<a href="data:image/svg+xml,…" download="filename.svg">I built a test to demonstrate: https://data-uri-test.glitch.me/
Presumably such leading junk is hidden in the rendered page, making the user think they're on MyBank.com?
it's even simpler than that, they add a bunch of spaces after the "fake" url to pad out the actual payload so it doesn't show in the urlbar. any issues with the page content can be fixed with document.write or whatever.
The phishers are using a URL like `data:text/html,https://example.com/account/xxxxx (lots of spaces here) <script>/* phish phish phish */</script>`
You won't see that scary <script> in the URL unless your browser window is super-wide.
The Idea is that the whole website could be a static file somewhere and the webserver is only a key value store that has no idea what it is saving. Doesn't work that way currently because file:/// doesn't allow ajax calls to somewhere else but that's a solveable problem.
Generally, every download that gets generated clientside by the JS is hit by this
Just curious-- why the exception for svg?
i.e.
data:image/svg+xml,<svg xmlns='http://www.w3.org/2000/svg'><script>alert('hi')</script></svg>